[root@nx74205 jail.d]# for conf in $(find $PWD -type f); do printf "=== %s ===\n%s\n\n" "$conf" "$(cat $conf)"; done
=== /etc/fail2ban/jail.d/00-firewalld.conf ===
# This file is part of the fail2ban-firewalld package to configure the use of
# the firewalld actions as the default actions. You can remove this package
# (along with the empty fail2ban meta-package) if you do not use firewalld
[DEFAULT]
banaction = firewallcmd-ipset[actiontype=<multiport>]
banaction_allports = firewallcmd-ipset[actiontype=<allports>]
=== /etc/fail2ban/jail.d/00-systemd.conf ===
# This file is part of the fail2ban-systemd package to configure the use of
# the systemd journal as the default backend. You can remove this package
# (along with the empty fail2ban meta-package) if you do not want to use the
# journal backend
[DEFAULT]
backend=systemd

But the dump of the config looks like it's using the iptables command.